Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
66,849 matching · page 1138/1337Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2023-32000(opens NVD record) | Medium | 4.8 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page. | Jul 8, 2023 |
| CVE-2023-20180(opens NVD record) | Medium | 4.3 | A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions. These actions could include joining meetings and scheduling training sessions. | Jul 7, 2023 |
| CVE-2023-20133(opens NVD record) | Medium | 5.4 | A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | Jul 7, 2023 |
| CVE-2022-4361(opens NVD record) | Critical | 10.0 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. | Jul 7, 2023 |
| CVE-2021-39014(opens NVD record) | Medium | 6.4 | IBM Cloud Object System 3.15.8.97 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213650. | Jul 7, 2023 |
| CVE-2023-37308(opens NVD record) | Medium | 5.4 | Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. | Jul 7, 2023 |
| CVE-2023-34197(opens NVD record) | Medium | 5.4 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications. | Jul 7, 2023 |
| CVE-2023-35890(opens NVD record) | Medium | 5.1 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637. | Jul 7, 2023 |
| CVE-2023-20899(opens NVD record) | High | 7.5 | VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. | Jul 6, 2023 |
| CVE-2023-3456(opens NVD record) | Medium | 5.3 | Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality. | Jul 6, 2023 |
| CVE-2023-37245(opens NVD record) | Critical | 9.1 | Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem. | Jul 6, 2023 |
| CVE-2023-37242(opens NVD record) | Critical | 9.8 | Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities. | Jul 6, 2023 |
| CVE-2023-37241(opens NVD record) | High | 7.5 | Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart. | Jul 6, 2023 |
| CVE-2023-37240(opens NVD record) | Critical | 9.1 | Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read. | Jul 6, 2023 |
| CVE-2023-37239(opens NVD record) | High | 7.5 | Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program. | Jul 6, 2023 |
| CVE-2023-37238(opens NVD record) | Medium | 5.3 | Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features. | Jul 6, 2023 |
| CVE-2023-34164(opens NVD record) | High | 7.5 | Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability. | Jul 6, 2023 |
| CVE-2023-1695(opens NVD record) | High | 7.5 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally. | Jul 6, 2023 |
| CVE-2023-1691(opens NVD record) | High | 7.5 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally. | Jul 6, 2023 |
| CVE-2022-48520(opens NVD record) | High | 7.5 | Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. | Jul 6, 2023 |
| CVE-2022-48519(opens NVD record) | High | 7.5 | Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. | Jul 6, 2023 |
| CVE-2022-48518(opens NVD record) | Medium | 5.5 | Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance. | Jul 6, 2023 |
| CVE-2022-48517(opens NVD record) | High | 7.5 | Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability. | Jul 6, 2023 |
| CVE-2022-48516(opens NVD record) | High | 7.5 | Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality. | Jul 6, 2023 |
| CVE-2022-48515(opens NVD record) | High | 7.5 | Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality. | Jul 6, 2023 |
| CVE-2022-48514(opens NVD record) | High | 7.5 | The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality. | Jul 6, 2023 |
| CVE-2022-48513(opens NVD record) | Critical | 9.8 | Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access. | Jul 6, 2023 |
| CVE-2022-48512(opens NVD record) | Critical | 9.8 | Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally. | Jul 6, 2023 |
| CVE-2022-48511(opens NVD record) | Critical | 9.8 | Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally. | Jul 6, 2023 |
| CVE-2022-48510(opens NVD record) | Critical | 9.8 | Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations. | Jul 6, 2023 |
| CVE-2022-48509(opens NVD record) | Medium | 5.9 | Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally. | Jul 6, 2023 |
| CVE-2022-48508(opens NVD record) | High | 7.5 | Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity. | Jul 6, 2023 |
| CVE-2022-48507(opens NVD record) | High | 7.5 | Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality. | Jul 6, 2023 |
| CVE-2021-46894(opens NVD record) | Critical | 9.8 | Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation. | Jul 6, 2023 |
| CVE-2021-46892(opens NVD record) | High | 7.5 | Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability may affect service confidentiality. | Jul 6, 2023 |
| CVE-2023-35001(opens NVD record) | High | 7.8 | Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace | Jul 5, 2023 |
| CVE-2023-33335(opens NVD record) | Medium | 6.1 | Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. | Jul 5, 2023 |
| CVE-2023-36934(opens NVD record) | Critical | 9.1 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. | Jul 5, 2023 |
| CVE-2023-36933(opens NVD record) | High | 7.5 | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly. | Jul 5, 2023 |
| CVE-2023-36932(opens NVD record) | High | 8.1 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. | Jul 5, 2023 |
| CVE-2023-35979(opens NVD record) | Medium | 5.3 | There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller. | Jul 5, 2023 |
| CVE-2023-35978(opens NVD record) | Medium | 6.1 | A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | Jul 5, 2023 |
| CVE-2023-35977(opens NVD record) | Medium | 6.5 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | Jul 5, 2023 |
| CVE-2023-35976(opens NVD record) | Medium | 6.5 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | Jul 5, 2023 |
| CVE-2023-35975(opens NVD record) | Medium | 6.5 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system. | Jul 5, 2023 |
| CVE-2023-35974(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Jul 5, 2023 |
| CVE-2023-35973(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | Jul 5, 2023 |
| CVE-2023-35972(opens NVD record) | High | 7.2 | An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS. | Jul 5, 2023 |
| CVE-2023-35971(opens NVD record) | High | 8.8 | A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | Jul 5, 2023 |
| CVE-2023-3455(opens NVD record) | Critical | 9.1 | Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity. | Jul 5, 2023 |